Study App Series Privacy Policy

This privacy policy describes how information is handled in the Study App Series (the "App"), a study app for certification and licensing exams available on iOS and Android.

Summary: the App does not require account registration. Data such as your learning history and progress is stored on your device, and we do not independently collect it. Only when you use an in-app purchase does the App send minimal information to a server we operate, to verify your purchase. We do not use tracking for advertising or analytics.

1. Operator

The App is provided by Legiotech, LLC ("we").

Address: Shiba, Minato-ku, Tokyo, Japan

For inquiries, see the "Contact" section below.

2. Our Approach

The App does not require account registration, and we do not collect information that directly identifies you, such as your name or email address, through normal use of the App.

However, if you use the contact form described below, we collect the name, email address, and other information you enter into that form. Please note that the scope of information collected differs between normal use of the App and use of the contact form. See the "Contact" section below for details.

3. Information Stored on Your Device

Your learning history, spaced-repetition (SM-2) progress, answer records, settings, and free-tier usage status are all stored on your device. None of this information is sent to our servers.

The export feature lets you save your learning history, spaced-repetition (SM-2) progress, settings, any paused session, and bookmarks to a file at your own discretion. Your free-tier usage status is not included in the export.

Data stored on your device may also be subject to OS-level backup mechanisms, such as Android's automatic backup feature or iOS's iCloud/iTunes backup. Whether data is sent to our servers and whether it is subject to an OS backup feature are two separate matters, and we ask that you keep both in mind.

4. Information Sent When You Purchase

When you make an in-app purchase, we send the following information to our receipt verification server (receipt-verify.svc.legiotech.jp, a general-purpose server we operate on Google Cloud Platform's Cloud Run and share across our apps) in order to verify your purchase.

The Bundle ID is sent in all cases. On iOS, we additionally send the signed transaction information issued by Apple (in JWS format, which carries a digital signature for tamper detection and is not itself encrypted; it includes the transaction ID, product ID, and purchase date). On Android, we additionally send the purchase token and product ID issued by Google Play.

Your Apple ID or Google Account itself, your name, and your email address are never sent.

5. Information We Store on Our Server

On our server, we store in Firestore (a Google Cloud database) only the information needed to verify the validity of your purchase and to activate or restore paid features.

The items we store are: the app's Bundle ID, an identifier for the purchase (such as a transaction ID), the product ID, an environment classification (production, sandbox, or Google Play), an entitlement classification based on whether a record already exists on our server, the transaction type, a validity flag, and related timestamps (such as the purchase date, last update time, and expiration time).

This classification does not record whether you performed a purchase or a restore action. If you restore a purchase after its server record has been deleted, it is classified as an initial grant because no existing record is present.

We use this information solely to provide and restore paid features.

6. Access Logs and IP Addresses

We process the IP address of each request to prevent unauthorized use and to operate the service reliably.

Sensitive values such as the receipt itself, the purchase token, and authorization credentials are masked before being logged and are never recorded in our logs.

7. Purpose of Use

We use the information we collect solely for the following purposes.

8. Provision to Third Parties

We provide or entrust information only to the following recipients, and only to the extent necessary. We do not provide or sell information for advertising purposes.

9. International Transfer

Our servers may operate on Google Cloud Platform, including locations outside Japan.

10. Analytics, Advertising, and Tracking

The App does not use advertising identifiers (IDFA / AAID) and does not track your behavior for advertising purposes.

The App includes no analytics SDK and no crash-reporting SDK.

11. Device Permissions

The App may use the following device permissions. Each is used only based on your own action or consent.

12. Retention

We retain purchase-related information on our server for as long as needed to provide and restore paid features.

Data stored on your device is removed from the device when you delete (uninstall) the App. See "Information Stored on Your Device" above regarding copies retained through OS backup features.

13. Your Rights and Deletion Requests

Using "Reset Learning" in the App clears your learning history, progress, and bookmarks. Your settings and free-tier usage status are not affected by this reset. To remove all data from your device, delete the App.

If you would like us to disclose or delete the purchase-related information stored on our server, please contact us. Please note that your purchase itself remains recorded with the App Store or Google Play, so if you use the App's "Restore Purchases" feature after deletion, re-verifying your purchase will recreate the corresponding information on our server.

14. Children's Privacy

We do not knowingly collect personal information from children.

15. Changes to This Policy

If we change the contents of this policy, we will announce the change by updating this page. The revised policy takes effect once it is posted on this page.

16. Contact

For inquiries about this policy, please contact us at the email address below.

You can also reach us through our online contact form. The form asks for your name, email address, subject, and message. The service your inquiry relates to, your display language, and the time of receipt are also recorded automatically. The information you provide is used solely to respond to your inquiry and is sent to our configured delivery destination. If no destination is configured, or if delivery fails, the information is recorded in server-side logs so our staff can review and respond (even in that case, the information is never used for any purpose other than responding to your inquiry). When recorded in logs, the message body is truncated to its first 500 characters.

sumik@legiotech.jp

Contact form

17. Revision History

September 9, 2026: Established.

If we change the contents of this policy, we will announce the change by updating this page.